Security Bulletin: IBM Planning Analytics Workspace is affected by vulnerabilities in Node.js (CVE-2022-43548, CVE-2020-7676, CVE-2021-42550, CVE-2021-38561, CVE-2022-32149)

## Summary IBM Planning Analytics Workspace is affected by vulnerabilities. Node.js is an open-source and cross-platform JavaScript runtime environment (CVE-2023-23918, CVE-2023-23920, CVE-2023-24807, ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Flea APT Targets Foreign Ministries with New Backdoor.Graphican

Threat Level Attack Report For a detailed threat advisory, download the pdf file here Summary Flea (APT15) targeted foreign ministries with their new backdoor, Backdoor.Graphican, leveraging Microsoft ...

Continue Reading
CVE-2023-30347

Cross Site Scripting (XSS) vulnerability in Neox Contact Center 2.3.9, via the serach_sms_api_name parameter to the SMA API search.Read More ...

Continue Reading
CVE-2023-34927

Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows attackers to arbitrarily change the victim user's ...

Continue Reading
php-imap vulnerable to RCE through a directory traversal vulnerability

### Summary An unsanitized attachment filename allows any unauthenticated user to leverage a directory traversal vulnerability which results in a remote code execution vulnerability. ### Details An at ...

Continue Reading
ScarCruft Hackers Exploit Ably Service for Stealthy Wiretapping Attacks

[![](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() The North Korean threat actor known as ScarCruft has been observed using an ...

Continue Reading
Chinese Hacker Group ‘Flea’ Targets American Ministries with Graphican Backdoor

[![Chinese Hacker Group](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() Foreign affairs ministries in the Americas have been tar ...

Continue Reading
Critical ‘nOAuth’ Flaw in Microsoft Azure AD Enabled Complete Account Takeover

[![Microsoft Azure AD OAuth](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() A security shortcoming in Microsoft Azure Active Dir ...

Continue Reading

Back to Main

Subscribe for the latest news: